Encryption at rest
Per-workspace AES-256 keys. Keys never leave the encryption boundary.
Security
We treat AI payloads as the most sensitive data we touch — they include unsent customer-facing copy, internal prompts, and operator decisions. Here is how the platform handles them.
Per-workspace AES-256 keys. Keys never leave the encryption boundary.
TLS 1.3 only. HSTS preloaded. Certificate pinning available on enterprise.
Per-workspace policy versions and rate limits. No cross-tenant fan-out paths.
Email + OAuth (Google, GitHub). OIDC SSO for enterprise. Forced password reset for invitations.
Workspace-scoped roles (Owner, Admin, Reviewer, Developer, Billing) plus platform Super Admin.
Immutable rows on every gate decision, dispatch, and admin action. Exportable on demand.
US default. EU and APAC on enterprise plans. Static residency per workspace.
Per-workspace + per-key quotas. Plan-based ceilings to prevent runaway costs.
Provider tokens and signing keys stored encrypted; rotation through dashboard or API.
Data in transit and at rest protected; privileged actions and pipeline changes written to an audit trail.
VerifiedData handling patterns designed for GDPR workflows.
VerifiedAccess is scoped to least privilege and audited actions.
VerifiedStandard DPA and sub-processor materials for enterprise procurement; execute via [email protected].
Verified